2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42183HIGH7.5MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.
CVE-2021-42242CRITICAL9.8A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.
CVE-2021-45783MEDIUM4.6Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to...
CVE-2021-41739CRITICAL9.8A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cy...
CVE-2021-42235CRITICAL9.8SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTic...
CVE-2021-43206MEDIUM4.3A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through...
CVE-2021-41032MEDIUM5.4An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an ...
CVE-2021-41020HIGH8.8An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated,...
CVE-2021-20051HIGH7.8SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijac...
CVE-2021-32010HIGH8.1Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitat...
CVE-2021-42185CRITICAL9.8wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.
CVE-2021-42192HIGH8.8Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to pri...
CVE-2021-43164HIGH8.8A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191...
CVE-2021-43163CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191...
CVE-2021-43162HIGH8.8A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191...
CVE-2021-43161HIGH8.8A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191...
CVE-2021-43160HIGH8.8A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191...
CVE-2021-43159HIGH8.8A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191...
CVE-2021-27439CRITICAL9.8TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of...
CVE-2021-27435CRITICAL9.8ARM mbed product Version 6.3.0 is vulnerable to integer wrap-around in malloc_wrapper function, which can lead to arbitr...
CVE-2021-27433CRITICAL9.8ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbed_krbs, which can lead ...
CVE-2021-27431CRITICAL9.8ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalen...
CVE-2021-27427CRITICAL9.8RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead ...
CVE-2021-27425CRITICAL9.8Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory as...
CVE-2021-27421CRITICAL9.8NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now